Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Frimousse 0.0.2 - 'explorerdir.php' Local Directory Traversal
CVE-2008-0425webappsphp
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary fi
23RIESGO
abrir
ReferênciaVexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Text-File Login script (SiTeFiLo) 1.0.6 - File Disclosure / Remote File Inclusion
CVE-2008-5762webappsphp
Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RIESGO
abrir
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir
ReferênciaVexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
CVE-2008-2856webappsphp
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
CVE-2006-4891webappsasp
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5774webappsphp
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RIESGO
abrir
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2863webappsphp
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RIESGO
abrir
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4115webappsphp
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Webquest 2.6 - Get Database Credentials
CVE-2008-0249webappsphp
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RIESGO
abrir
ReferênciaVexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
CVE-2008-5773webappsasp
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
CVE-2008-6269webappsphp
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
CVE-2008-6723webappsphp
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir
ReferênciaVexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
CVE-2008-7007webappsphp
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir
ReferênciaVexDay Proof
Link ADS 1 - 'linkid' SQL Injection
CVE-2008-2869webappsphp
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
ShareCMS 0.1 - Multiple SQL Injections
CVE-2008-2870webappsphp
Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1726webappsphp
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
CVE-2008-4484webappsphp
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RIESGO
abrir
ReferênciaVexDay Proof
Enthusiast 3.1.4 - 'show_joined.php' Remote File Inclusion
CVE-2008-5792webappsphp
PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Authentication Bypass
CVE-2008-6302webappsphp
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a dir
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6965webappsphp
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when
23RIESGO
abrir
ReferênciaVexDay Proof
MyPicGallery 1.0 - Arbitrary Add Admin
CVE-2008-2347webappsphp
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
odars CMS 1.0.2 - Remote File Inclusion
CVE-2008-2885webappsphp
PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital
23RIESGO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - Insecure Cookie Handling
CVE-2008-4081webappsphp
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by settin
23RIESGO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Insecure Cookie Handling
CVE-2008-4714webappsphp
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which proba
23RIESGO
abrir
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'id' SQL Injection
CVE-2006-4715webappsphp
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Insecure Cookie Handling
CVE-2008-6009webappsphp
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the
23RIESGO
abrir
ReferênciaVexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
CVE-2008-6411webappsphp
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir
ReferênciaVexDay Proof
A+ PHP Scripts - Nms Insecure Cookie Handling
CVE-2008-6667webappsphp
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.